xn--harmonesas-p8aa[.]com
“HarmonieSas Bank - Fraudulent Transfer Refund Process”
xn--harmonesas-p8aa.com — Non verificato. Simulazione del marchio: ["google"]; Tipo di truffa: Credential Phishing. Riepilogo delle prove: VirusTotal 6/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Fortinet, Gridinsoft); Spamhaus DBL_PHISH; PhishDestroy score 68/100. Registrar: NiceNIC.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
This domain, xn--harmonesas-p8aa.com, is a phishing site designed to impersonate HarmonieSas Bank and harvest user credentials under the pretext of a fraudulent transfer refund process. The page title, 'HarmonieSas Bank - Fraudulent Transfer Refund Process,' explicitly targets customers of the legitimate financial institution by exploiting trust in banking procedures. Such infrastructure is commonly used to collect login credentials, personal identification details, and financial data, which are later exploited for unauthorized transactions or sold on underground forums. Analysis indicates the domain employs social engineering tactics to create urgency, pressuring victims into divulging sensitive information without verifying the authenticity of the request. Infrastructure analysis reveals multiple technical indicators of malicious activity. The domain is flagged by 6 out of 95 security vendors on VirusTotal, indicating moderate detection but not universal recognition as a threat. It resolves to the IP address 46.62.199.254 and appears on at least one security blocklist, suggesting prior identification as part of phishing campaigns. Registered through NICENIC INTERNATIONAL GROUP CO., LIMITED on April 21, 2026, the domain leverages an international registrar known for hosting high-risk domains. The creation date, set in the future, is anomalous and may indicate an attempt to evade automated detection systems that rely on domain age as a trust factor. Additionally, the domain has a Gridinsoft trust score of 0/100, further corroborating its malicious intent. Users who visited xn--harmonesas-p8aa.com should take immediate action to mitigate potential risks. If any credentials or personal information were entered, affected individuals must change their HarmonieSas Bank login details and enable multi-factor authentication on all financial accounts. Financial institutions should be notified of the exposure to monitor for unauthorized transactions. System scans using updated security tools are recommended to detect any secondary infections or data exfiltration. Users should also review browser history and installed extensions for signs of compromise, as phishing sites may deploy additional malicious payloads. Future vigilance is advised when interacting with unsolicited banking communications, particularly those requesting urgent action or sensitive data.
Informazioni sulla sicurezza di rete Registrar context
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-13 02:39:07 UTC
Analisi di VirusTotal
Dati e relazioni esterne
PD-20260421-76545E Recipient: abuse@hetzner.com Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo